In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
References
Configurations
History
21 Nov 2024, 03:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.suse.com/show_bug.cgi?id=1045735 - | |
References | () https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html - | |
References | () https://www.suse.com/de-de/security/cve/CVE-2017-9269/ - | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 7.7 |
07 Nov 2023, 02:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html - | |
References | () https://bugzilla.suse.com/show_bug.cgi?id=1045735 - | |
References | () https://www.suse.com/de-de/security/cve/CVE-2017-9269/ - |
Information
Published : 2018-03-01 20:29
Updated : 2024-11-21 03:35
NVD link : CVE-2017-9269
Mitre link : CVE-2017-9269
CVE.ORG link : CVE-2017-9269
JSON object : View
Products Affected
opensuse
- libzypp